ended4월 4일· 4 sources
OpenClaw Critical Flaw: How a Single Validation Bug Exposed 135K Instances
OpenClaw 심각한 결함: 페어링 검증 미흡으로 13.5만 인스턴스 위험
Why it matters
OpenClaw's pairing approval mechanism fails to validate user permissions, allowing anyone with basic access to grant themselves admin rights in under 30 seconds. With 135,000+ instances publicly exposed and 63% running zero authentication, the trivial exploit path has almost certainly been weaponized since the two-day window between patch and public disclosure. Immediate patching to version 2026.3.28 and forensic auditing are essential for all affected organizations.
4
Sources
+0
24h
—
Growth
170d
Active
ai agentauthentication bypassauthorization bypasscve-2026-33579device pairingopenclawprivilege escalationscope validationsecurity patch
Sources
hackernews
If you're running OpenClaw, you probably got hacked in the last week4월 4일
arstechnicaOpenClaw gives users yet another reason to be freaked out about security4월 4일
devtoOpenClaw CVE-2026-33579: Unauthorized Privilege Escalation via `/pair approve` Command Fixed4월 4일
geeknewsOpenClaw 권한 상승 취약점 (CVE-2026-33579)4월 4일